Attackers are using fake Telegram groups and Twitter accounts to target crypto users with sophisticated scam tactics

Source Cryptopolitan

Web3 anti-scam platform Scam Sniffer has identified a new strategy by crypto scammers to target users on Telegram. In a post on X, the platform observed that these bad actors now use fake Telegram groups and the impersonation of crypto personalities.

According to Scam Sniffer, crypto bad actors rely heavily on the Telegram Safeguard Bot scam to access users’ devices and steal funds. They create fake X (formerly Twitter) accounts that impersonate crypto influencers.

They use these impersonated accounts to comment on legitimate posts, asking users to join their Telegram groups, where they share alpha and insights. However, users who join these groups are immediately prompted to verify a fake OfficialSafeguardBot.

Any user who verifies will unwittingly inject malicious PowerShell code into their clipboard. Upon executing the command, it downloads and operates malware that can compromise devices and crypto wallets. SlowMist founder Yu Xian, popularly known as Cos, noted that the malware is a Trojan horse. He said:

“When you run this Powershell command, a more complex Powershell malicious code will be downloaded covertly, and eventually the Remcos remote control Trojan will be implanted in your computer, thus compromising your computer.”

Cos further explained that there is another Telegram Safeguard scam where hackers trick users into releasing their account information. The scam tries to hack users’ Telegram accounts by asking for their mobile phone numbers or requesting that they scan a QR code and provide their login code and the two-step verification password, allowing it to control the account fully.

Fake crypto accounts are growing on X again

Meanwhile, the prevalence of the Telegram scams has also led to a rise in the number of fake crypto accounts on Twitter over the last few days. ScamSniffer reported that its monitoring systems discovered an average of 300+ fake accounts daily over the past week.

This represents a significant surge from the average of 160+ throughout November and highlights the return of the fake accounts problem to X (formerly Twitter). Although the issue appeared to have been resolved earlier this year, the resurgence in crypto prices has also led to increased crypto impersonations, suggesting a correlation between the two.

Fake Crypto Accounts
Fake crypto accounts on X rose by 87% in December (Source: Scam Sniffer)

X impersonations rose significantly between November 29 and early December, when Bitcoin rallied and broke the $100,000 mark. However, they now appear to declined, just as Bitcoin and other major caps also recorded price corrections.

These fake accounts have already made millions of unwitting victims who clicked on the malicious links. Scam Sniffer reported that two victims recently lost over $3 million to these malicious links. Several other victims also lost funds after clicking on phishing comments from fake accounts under the Pudgy Penguins tweets.

Interestingly, scammers are not just creating fake accounts; they are also compromising popular accounts to push crypto scams.

Scam Sniffer recommended several protection tips, including avoiding unknown links and software, verifying official channels, and being cautious of any time-pressured verification. As the anti-scam watchdog noted, crypto scams continue to evolve beyond simple phishing, and it is important to stay vigilant.

From Zero to Web3 Pro: Your 90-Day Career Launch Plan

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Gold price moves closer to three-week peak amid modest USD downtickGold price (XAU/USD) attracts some dip-buying during the Asian session on Tuesday and reverses a major part of the previous day's retracement slide from a nearly three-week high.
Author  FXStreet
Yesterday 08: 26
Gold price (XAU/USD) attracts some dip-buying during the Asian session on Tuesday and reverses a major part of the previous day's retracement slide from a nearly three-week high.
placeholder
S&P 500 hits a new all time of 6,300 for the first time everThe S&P 500 broke through 6,300 for the first time in history on Tuesday, as rising demand for crypto stocks and tech names sent U.S. markets higher across the board.
Author  Cryptopolitan
23 hours ago
The S&P 500 broke through 6,300 for the first time in history on Tuesday, as rising demand for crypto stocks and tech names sent U.S. markets higher across the board.
placeholder
Japan’s bond market is falling apart in real time after bond values crashJapan’s bond market is falling apart in real time. The 30-year Japanese bond yield jumped to 3.20%, a fresh record.
Author  Cryptopolitan
22 hours ago
Japan’s bond market is falling apart in real time. The 30-year Japanese bond yield jumped to 3.20%, a fresh record.
placeholder
EUR/USD sinks towards 1.1600 as US inflation rises and crushes Fed cut hopesThe EUR/USD fell some 0.55% on Tuesday after the latest US inflation report revealed that prices are edging higher, justifying the Federal Reserve's current policy stance.
Author  FXStreet
7 hours ago
The EUR/USD fell some 0.55% on Tuesday after the latest US inflation report revealed that prices are edging higher, justifying the Federal Reserve's current policy stance.
placeholder
Japanese Yen remains vulnerable near multi-month low against USDThe Japanese Yen (JPY) hit a fresh low since April against its American counterpart during the Asian session on Wednesday.
Author  FXStreet
5 hours ago
The Japanese Yen (JPY) hit a fresh low since April against its American counterpart during the Asian session on Wednesday.
goTop
quote